Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-24 · updated: 2026-09-24 · tags: [incident, global, macos] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

Unknown actors compromised legitimate MemTensor packages on npm and PyPI to deliver sckit, a platform-specific Go implant for Windows, Linux and macOS. The affected versions are @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23 and 0.1.25 (0.1.22 and 0.1.24 are clean) and PyPI MemoryOS 2.0.34, now quarantined. The npm launcher fires when the agent gateway starts and on every memory-recall event, passing the host environment — and during recall, the user's prompt text — to the payload; the PyPI build starts on import of the memos module. Exfiltration goes to skyleen[.]fr, harvesting npm, PyPI, GitHub, GitLab, AWS, Vault and SSH secrets, .npmrc, .vault-token, id_ecdsa, access_tokens.json and tokens for Hugging Face, Slack, Stripe and SendGrid, with a worm-like capability to self-propagate through GitHub and registry publishing. OpenSourceMalware's verified record for memoryos gives the campaign an attribution the news coverage does not carry: it classifies the package as legitimate-but-compromised, severity critical, and names the payload family PolinRider, associated with DPRK/Lazarus, with data exfiltration, code execution, network activity and obfuscation behaviours. SafeDep traces the initial access to MemTensor's own GitHub Actions release pipelines, where commits caused the workflow to hand over the npm and PyPI publish tokens.

Attribute Detail
Sector Global (Macro)
Date 2026-09-24
Source OpenSourceMalware
Reliability Tier 2